Bug 2501687 - CVE-2026-59886 python38-pyasn1-epel: pyasn1: Denial of Service via crafted ASN.1 REAL values [epel-all]
Summary: CVE-2026-59886 python38-pyasn1-epel: pyasn1: Denial of Service via crafted AS...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: python38-pyasn1-epel
Version: epel10
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Orion Poplawski
QA Contact:
URL:
Whiteboard: {"flaws": ["2093750a-1526-4320-bd42-8...
Depends On:
Blocks: CVE-2026-59886
TreeView+ depends on / blocked
 
Reported: 2026-07-17 07:26 UTC by Jeremy Choi
Modified: 2026-07-17 07:26 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jeremy Choi 2026-07-17 07:26:16 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.


Note You need to log in before you can comment on or make changes to this bug.